IT Brief US - Technology news for CIOs & IT decision-makers
United States
Google Cloud sets 2029 roadmap for quantum-safe shift

Google Cloud sets 2029 roadmap for quantum-safe shift

Tue, 11th Aug 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

Google Cloud has set out a roadmap to migrate its infrastructure and services to post-quantum cryptography by 2029, covering both internal systems and customer-facing products.

The plan outlines milestones across network traffic, digital signatures, identity controls, key management and hardware-backed security. Some work is already complete, while other targets extend into the 2030s as standards evolve and older algorithms are phased out.

Post-quantum cryptography is intended to protect data and authentication systems against a future quantum computer capable of breaking widely used cryptographic methods. Google Cloud said its approach focuses on three priorities: reducing the risk that encrypted data collected today could be decrypted later, strengthening signatures against forgery, and building systems that can adopt new standards with less disruption.

As an immediate step, Google Cloud's API endpoints now offer quantum-safe key exchange for incoming traffic, including google.com and googleapis.com endpoints, using the NIST-standardised ML-KEM algorithm in hybrid mode. Application and proxy load balancers also support hybrid key exchange for TLS 1.3 on an opt-in basis.

That allows customers to begin testing post-quantum handshakes on internet-facing services before broader deployment across their own environments. Cloud KMS now generally offers NIST-standardised post-quantum algorithms, including ML-KEM, ML-DSA and SLH-DSA, for encryption and signing keys.

Three domains

The first part of the plan targets so-called Store Now, Decrypt Later risks, in which attackers capture encrypted traffic now in the hope of reading it once quantum systems become viable. Google Cloud is aiming to complete this phase by the end of 2027.

Services in that timeframe include Cloud VPN, Cloud Interconnect, GCE OS Login, Cloud SDK, gCloud CLI, GKE service mesh and client libraries, along with work on Cloud Storage SDK, Storage Transfer Service, BigQuery CLI and Data Transfer Service.

The second domain covers integrity and non-repudiation, with a target date of the end of 2028. It includes software supply chain controls, certificate systems and identity services intended to make forged credentials or tampered software harder to present as legitimate.

Products in this part of the roadmap include Binary Authorization, Access Approval, Assured OSS, Private CA through Certificate Authority Service, Google Trust Service and Cloud IAM. Google Cloud is also planning a broader rollout of post-quantum certificates and authentication across its products and infrastructure during 2027 and 2028.

The third domain also runs to the end of 2028 and covers foundations such as key management libraries, confidential computing, hardware security modules, external key management and sovereignty-related partner solutions. Quantum-safe key import is due in 2026, while Confidential Compute and a quantum-safe Cloud HSM are scheduled for 2028.

Standards work

Google Cloud tied parts of the roadmap to standards work beyond its own platforms. Certificate migration will follow development at the Internet Engineering Task Force, and the company pointed to experiments with Merkle Tree Certificates as one possible way to manage the larger signatures associated with some post-quantum schemes.

It said Chrome and Cloudflare have already begun experiments in this area and that Google Cloud has been sharing its findings with the relevant standards group. The company is also contributing to certificate standards intended to support ML-DSA and, where relevant, SLH-DSA.

The broader timeline reflects government and industry planning now under way in the US. Google Cloud pointed to guidance that anticipates the withdrawal of older quantum-vulnerable algorithms between 2030 and 2035, even after its own target date for post-quantum readiness.

Shared responsibility

Google Cloud framed the migration as a shared responsibility between provider and customer. It will handle changes to the security of the cloud, including networks, global front ends, server infrastructure and transport protocols, while customers remain responsible for their own applications, client software, key lifecycle management and service configuration.

Hardware replacement may take longer in some cases because physical infrastructure must move through a mix of active replacement and normal refresh cycles. As a result, some hardware-related elements may continue beyond 2029.

For customers, Google Cloud recommended three starting steps: inventory cryptographic assets, update software used by development and site reliability teams, and validate application behaviour against its quantum-safe APIs and load balancers. Those steps are intended to surface older dependencies and compatibility issues before organisations move critical production systems to the newer cryptographic settings.

The roadmap also extends to sovereign cloud work, including Google Cloud Dedicated and Google Distributed Cloud, and to AI-related services that will need similar protections as quantum-safe migration spreads across cloud workloads.

Google Cloud said: "We plan to achieve full PQC readiness by 2029, when our efforts converge."